Is Plaud HIPAA Compliant? Kind Of. Here's What to Know (2026)
Independently fact-checked against primary sources (last audited August 5, 2026). · Law checked current as of August 9, 2026. · 18 primary sources cited on this page. How we verify our legal content

Plaud holds HIPAA certification verified through a third-party assessment and maintains SOC 2 Type II, ISO 27001, and AES-256 encryption. However, healthcare providers cannot legally use it with patient data without a signed Business Associate Agreement (BAA), required under HIPAA for any vendor handling Protected Health Information, and Plaud has not publicly offered one.
Last updated: August 4, 2026
If you are a healthcare professional considering the Plaud NotePin for recording patient sessions, you have probably asked the same question everyone else is asking: Is Plaud HIPAA compliant?
The short answer is yes, kind of. Plaud has obtained HIPAA certification, and their security stack is genuinely impressive. But there is a critical gap between "HIPAA certified" and "safe to use with patient data" that every clinician needs to understand before pressing record.
This guide breaks down exactly what Plaud's compliance covers, where the gaps are, how state recording laws create additional legal exposure, and what you need to do to protect yourself and your patients.
What Plaud's HIPAA Compliance Actually Means
Plaud has built one of the more robust security frameworks in the AI recording space. Their trust page and Drata compliance portal document an impressive list of certifications.

Plaud's Security Certifications
Here is what Plaud currently holds:
- SOC 2 Type II: Independent audit validating security, availability, processing integrity, confidentiality, and privacy controls
- HIPAA: Healthcare data protection compliance verified through third-party assessment
- GDPR: Full EU data protection compliance (achieved July 2025)
- CCPA/CPRA: California consumer privacy compliance
- ISO 27001: Information security management standard
- ISO 27701: Privacy information management standard
- EN 18031: Hardware physical and logical security
Encryption and Data Protection
Plaud's technical security measures include:
- TLS encryption in transit with a secondary application-level encryption layer using unique keys
- AES-256 encryption at rest for all stored data
- On-device AES-256 chip-level encryption on the NotePin hardware, so data cannot be read without paired account credentials even if the physical device is stolen
- AWS US West (Oregon) infrastructure, a SOC 2 and ISO 27001 certified data center
- Zero-training guarantee in their 2026 Enterprise Terms. Patient data is processed through isolated instances and deleted from processing cache after transcription is finalized
This is genuinely solid for a consumer-grade AI recording device. But here is where the story gets complicated.
The BAA Problem: Why HIPAA Certification Is Not Enough
Here is the critical nuance that Plaud's marketing buries: HIPAA certification for a vendor is not the same as making your healthcare use automatically compliant.
First, a clarification. There is no official government-issued "HIPAA certification." What Plaud means, and what is standard industry practice, is that they have undergone independent third-party assessment and their controls meet HIPAA requirements. That is legitimate, but it is only one piece of the compliance puzzle.
What Is a Business Associate Agreement?
Under HIPAA, any third-party vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a healthcare provider must sign a Business Associate Agreement (BAA). This is a legally binding contract required by federal law.
A BAA must include:
- Permitted and required uses of PHI
- Obligation not to use PHI beyond what the contract allows
- Requirement to implement administrative, physical, and technical safeguards
- Breach notification procedures
- Subcontractor compliance provisions
- PHI return or destruction at contract termination
- HHS access to records for compliance audits
Does Plaud Offer a BAA?
This is where the gap exists. Despite extensive review of Plaud's support documentation, enterprise FAQ, trust page, healthcare solution page, and blog posts, there is no public evidence that Plaud offers a Business Associate Agreement.
Their healthcare marketing is aggressive. They run a dedicated healthcare solution page, SOAP note templates, clinical note formatting, and a healthcare professionals discount. None of these materials mention a BAA.
This creates a paradox. Plaud markets directly to healthcare professionals while apparently not providing the one legal document that healthcare professionals need before using any recording tool with patient data.
What Happens If You Use Plaud Without a BAA?
Using any tool that handles PHI without a signed BAA is itself a HIPAA violation, regardless of how strong the tool's security features are. The consequences are serious:
| Tier | Culpability | Per Violation | Annual Cap |
|---|---|---|---|
| 1 | Lack of knowledge | $145 to $73,011 | $25,000 |
| 2 | Reasonable cause | $1,461 to $73,011 | $100,000 |
| 3 | Willful neglect (corrected within 30 days) | $14,602 to $73,011 | $250,000 |
| 4 | Willful neglect (not corrected) | $73,011 to $2,190,294 | $2,190,294 |
These penalty amounts were updated January 28, 2026 by HHS. One caveat on the annual caps: the statutory inflation adjustment sets a single $2,190,294 calendar-year cap for identical violations, and the lower tier-by-tier caps trace to an HHS enforcement policy adopted in 2019 that was never formally codified. Treat the lower caps as enforcement practice rather than a fixed statutory limit.
Under the HITECH Act, both the covered entity (you, the healthcare provider) and the business associate (Plaud) can face enforcement.
Beyond fines, a HIPAA violation can trigger loss of Medicare/Medicaid contracts, mandatory corrective action plans, increased regulatory oversight, and reputational damage. In cases of willful neglect, criminal penalties including prison time are possible.
Bottom line: If you are a healthcare provider, contact Plaud directly and get a signed BAA in writing before using it with any patient data. Without one, you are exposed regardless of their certifications.
One-Party vs. All-Party Consent: The Bigger Practical Problem
Even with perfect HIPAA compliance, recording conversations introduces a second layer of legal risk that many Plaud users overlook: state recording consent laws.
Plaud's own guidance on consent is surprisingly thin. Their website essentially says to take a moment to let others know and get their okay before recording. That is legally inadequate in many jurisdictions.
Federal Law: The Baseline
The federal Wiretap Act (18 U.S.C. § 2511) prohibits intercepting communications but includes a critical exception: recording is lawful when one party to the communication has given prior consent. This makes federal law a one-party consent standard.
Federal violations carry up to 5 years imprisonment and fines up to $250,000. Civil remedies under 18 U.S.C. § 2520 allow actual or statutory damages plus attorney's fees.
But federal law sets a floor, not a ceiling. States can and do impose much stricter requirements.
All-Party Consent States (2026)
The following states require every participant to consent before recording begins, at least for some categories of private conversation:
| State | Statute | Criminal Penalty |
|---|---|---|
| California | Penal Code § 632 | Up to $2,500 fine + 1 year jail; $10,000 for repeat offenders |
| Connecticut | Conn. Gen. Stat. § 52-570d | Civil liability for telephone recordings (one-party for criminal) |
| Delaware | 11 Del. Code § 1335 | Class A misdemeanor under § 1335(c). The separate wiretap statute, 11 Del. C. § 2402, is a class E felony but exempts a party to the conversation |
| Florida | Fla. Stat. § 934.03 | Third-degree felony: up to 5 years + $5,000 fine |
| Illinois | 720 ILCS 5/14-2 | Felony: 1 to 3 years prison + $25,000 fine |
| Maryland | Md. Code § 10-402 | Felony: up to 5 years + $10,000 fine |
| Massachusetts | Ch. 272, § 99 | Up to $10,000 fine + 5 years prison |
| Montana | Mont. Code § 45-8-213 | Up to 6 months (first offense); up to 5 years + $10,000 (third+) |
| New Hampshire | RSA 570-A:2 | Class B felony |
| Oregon | ORS 165.540(1)(c) | Class A misdemeanor (applies to in-person conversations) |
| Pennsylvania | 18 Pa.C.S. § 5703 | Third-degree felony: up to 7 years + $15,000 fine |
| Washington | RCW 9.73.030 | Gross misdemeanor |
Note on Oregon, and why it matters most for a wearable. Oregon splits its rule by medium, and the split runs the opposite way from Nevada's. ORS 165.540(1)(c) makes it unlawful to obtain any part of a conversation with a recording device "if not all participants in the conversation are specifically informed that their conversation is being obtained," while subsection (1)(a) applies a one-party consent standard to telecommunications and radio communications. A violation is a Class A misdemeanor. Because the Plaud NotePin is worn during in-person encounters, Oregon's stricter in-person rule is the one that governs most Plaud use in that state.
Note on Nevada: Nevada has a hybrid rule running the other direction. Nevada law requires all-party consent for telephone calls (NRS 200.620) but only one-party consent for in-person conversations.
Note on Michigan: Michigan's status remains legally ambiguous. The statute (MCL 750.539c) technically requires all-party consent, but Michigan courts have interpreted it to allow participant recording. The Michigan Supreme Court declined to resolve the question definitively, creating ongoing legal uncertainty.
One-Party Consent States
In the remaining states, including New York, Texas, and Virginia, you can legally record a conversation as long as you are a participant. You do not need to inform the other parties. See the full list of one-party consent states.
The Cross-State Problem
When call participants are in different states, things get complicated fast. The leading case is Kearney v. Salomon Smith Barney, Inc. (2006), where the California Supreme Court ruled that California's all-party consent law applied to calls recorded by employees in Georgia (a one-party state) involving California clients.
The practical rule: if any participant is in an all-party consent state, treat the entire conversation as requiring all-party consent. There is no definitive federal rule resolving cross-state conflicts, and the most protective standard is the safest approach.
This is particularly relevant for telehealth providers. If you are a doctor in Texas (one-party consent) with a patient calling from California (all-party consent), California law likely applies and you need that patient's explicit consent.
The AI Layer: New Legal Complications
Using AI-powered recording devices like the Plaud NotePin introduces legal dimensions that did not exist with traditional recording equipment.
Existing Wiretap Laws Apply to AI
Courts have applied existing wiretap and eavesdropping laws to AI-powered recording and transcription. The technology does not change the consent obligation. Whether a human or an AI listens to the recording, the same rules apply.
Key AI-Specific Developments
California AB 2905 (chaptered 2024) amended Public Utilities Code section 2874, which governs calls placed using automatic dialing-announcing devices. The required announcement must state the nature of the call along with the name, address, and telephone number of the business being represented, ask whether the person called consents to hear the prerecorded message, and inform the person called if the prerecorded message uses an artificial voice. The bill defines an artificial voice as one "generated or significantly altered using artificial intelligence."
Read the scope carefully. AB 2905 targets outbound prerecorded calling, not wearable recorders, and the bill text sets no separate dollar penalty. It signals where AI disclosure duties are heading rather than imposing a rule that governs NotePin use.
The FCC confirmed in February 2024 that AI-generated voices qualify as "artificial or pre-recorded voices" under the Telephone Consumer Protection Act. AI-generated calls cannot evade TCPA coverage.
Illinois BIPA and AI voiceprints present a particularly sharp risk for Plaud users. Illinois's Biometric Information Privacy Act defines a biometric identifier to include a "voiceprint" (740 ILCS 14/10). AI transcription tools that use speaker identification, a feature Plaud actively promotes, may trigger BIPA requirements including written notice, signed authorization, and a public retention policy. BIPA carries a private right of action with liquidated damages of $1,000 for each negligent violation and $5,000 for each intentional or reckless violation, plus attorneys' fees (740 ILCS 14/20). That fee-shifting private right of action is why BIPA drives class litigation against transcription vendors.
Cruz v. Fireflies.AI Corp. (C.D. Ill. No. 3:25-cv-03399, filed December 18, 2025) alleged that an AI meeting assistant violated BIPA by distinguishing speakers without BIPA-compliant notice. The docket shows the case terminated on March 11, 2026. A complaint is an allegation, not a holding, so treat this case as evidence of the theory plaintiffs are testing rather than a rule any court has adopted, and check the docket for its current posture before relying on it.
The Capability Test: A Major Expansion of Exposure
In Ambriz v. Google LLC (N.D. Cal. No. 23-cv-05437-RFL, February 10, 2025), the court denied Google's motion to dismiss and applied what is now called the "capability test." At the pleading stage, the court held that alleging an AI vendor has the technical capability to use intercepted data for its own benefit, regardless of whether the vendor actually does so, is sufficient to plead that the vendor is a third-party eavesdropper under California's Invasion of Privacy Act.
A ruling on a motion to dismiss is not a final merits decision, but the reasoning still expands legal exposure for AI recording vendors. If a vendor's terms of service permit using customer data to improve its products, even where the vendor does not currently do so, that capability alone could support a CIPA claim in California.
The Otter.ai Warning
In Brewer v. Otter.ai (August 2025), a class action alleged that Otter's AI notetaker recorded private conversations of meeting participants who were not Otter subscribers, without proper consent. The case highlights a risk applicable to all AI recording tools: default settings that do not seek consent from all parties in a conversation.
Healthcare Recording: Where HIPAA Meets Consent Law
For healthcare professionals, the legal analysis gets especially layered. You must comply with both HIPAA and your state's recording consent laws simultaneously.
HIPAA Does Not Directly Address Recording
HIPAA does not have a specific provision about audio recording. However, any recording containing Protected Health Information falls under HIPAA's privacy and security rules. This means:
- Patient consent is required before recording conversations about their care
- You must explain why recordings are necessary and how they will be used
- All recordings must be encrypted and securely stored
- A BAA is required with any third-party recording service that processes PHI
The Sharp HealthCare Lawsuit: A Cautionary Tale
In a proposed class action filed in San Diego Superior Court and reported in December 2025, Sharp HealthCare was accused of secretly recording exam room conversations during its rollout of Abridge, an ambient AI clinical documentation tool, with more than 100,000 patients potentially affected. The complaint alleged that the AI system automatically inserted false consent statements into patient records, documenting that patients "were advised" the visit was being recorded and that they "consented" when that had not happened.
This case demonstrates exactly what can go wrong when healthcare organizations adopt AI recording tools without rigorous consent practices.
State Medical Privacy Laws Go Further
HIPAA creates a federal floor, but many states impose additional protections:
- In one-party consent states, patients can technically record clinical encounters without the provider's knowledge
- In all-party consent states, covert recording of doctor visits is illegal for everyone
- California AB 3030, signed September 28, 2024, added Chapter 2.13 (commencing with section 1339.75) to Division 2 of the Health and Safety Code. It requires health facilities, clinics, physician's offices, and offices of a group practice that use generative AI for patient communications about clinical information to include a disclaimer identifying the communication as AI-generated, along with instructions for contacting a human provider. The disclaimer requirement does not apply where a licensed health care provider reads and reviews the AI-generated communication before it is sent.
A proposed HIPAA Security Rule update published in January 2025, the first major revision in roughly 20 years, would remove the distinction between "required" and "addressable" safeguards and impose stricter encryption and risk management requirements on systems processing PHI. Proposed rules change before they are finalized, so confirm its current status before building a compliance program around it.
What This Means Practically for Plaud Users
Here is a quick-reference risk assessment for common Plaud use cases:
| Scenario | Risk Level | Notes |
|---|---|---|
| Recording yourself (memos, voice notes) | Low | No consent issue, you are the only party |
| In-person meeting, everyone informed | Low | Fine in all states with verbal consent |
| Phone/video call, one-party consent state | Low | Legal as long as you are a participant |
| Phone/video call, any all-party state involved | Medium | Must notify and get consent from all parties |
| Business meeting with participants in multiple states | Medium | Apply the strictest state's law |
| Healthcare recording with signed BAA | Medium | Compliant if patient consents and data is secured |
| Healthcare recording without BAA | High | Potential HIPAA violation regardless of state |
| Covert recording in CA, FL, IL, MD, MA, OR, PA, WA, and similar states | High | Criminal exposure, felony charges possible in several |
| Recording in Illinois with speaker identification enabled | High | Potential BIPA violation ($1,000 to $5,000 per violation) |
HIPAA-Compliant Alternatives That Offer BAAs
If you need a recording and transcription tool for healthcare use and want the BAA question settled upfront, some alternatives publicly document Business Associate Agreements. Not all of them do, and we hold competitors to the same evidentiary standard we hold Plaud to. The column below reflects what each vendor's own current materials said when we checked in August 2026:
| Solution | BAA Publicly Documented | Key Differentiator |
|---|---|---|
| DeepScribe | Yes: privacy policy describes handling PHI as a HIPAA business associate under a BAA with each customer | AI ambient scribe with human QA review |
| Freed | Yes: "We also sign Business Associate Agreements (BAAs) with healthcare organizations" | Deletes patient recordings automatically once the note is complete |
| Supanote | Yes: publishes its BAA on its website | SOAP/DAP/progress notes, designed for therapy practices |
| Fireflies.ai | Yes, Enterprise plan only | 0-day retention option; states meeting data is not used for AI training |
| Nabla | Not publicly stated. Its trust portal lists HIPAA, SOC 2, and ISO 27001 but no BAA language. Confirm with the vendor in writing | Clinical notes in under 20 seconds |
| Otter.ai | Not stated by name. Pricing page lists "HIPAA compliance (add-on)" on Enterprise only. Confirm the BAA in writing before any PHI use | General-purpose meeting transcription, not healthcare-specific |
Verify before you rely on this table. Vendor pages change, tiers get restructured, and a BAA only protects you once it is signed and countersigned. Ask each vendor in writing which contracting tier includes the BAA, and keep the executed copy. Treat any vendor's marketing claim about HIPAA as a starting point for that conversation, not as the agreement itself.
None of these are perfect replacements for the Plaud NotePin's physical form factor. Plaud's hardware, a lightweight wearable that clips to clothing with one-button operation and offline recording, remains well suited for in-person clinical encounters. The tradeoff is between hardware convenience and compliance certainty.
Best Practices for Using Plaud Legally
Whether you are in healthcare or business, following these practices will minimize your legal exposure when using any AI recording device.
For All Users
-
Default to all-party consent. Even in one-party consent states, informing all parties is the safest practice and avoids cross-state complications.
-
Announce recording at the start of every conversation. A simple "I would like to record this conversation for my notes. Is that okay with everyone?" is sufficient in most jurisdictions.
-
Document consent. Keep a log of who consented, when, and how. For important conversations, get written consent.
-
Check state laws before recording. If you are unsure whether a conversation touches an all-party consent state, assume it does. Remember that Oregon's all-party rule applies to the in-person conversations a wearable is most likely to capture.
-
Disable speaker identification in Illinois. If any participant is in Illinois, Plaud's speaker recognition feature could trigger BIPA liability.
-
Review Plaud's data retention settings. Understand where your recordings are stored, for how long, and whether they are used for any purpose beyond transcription.
For Healthcare Professionals
-
Get a BAA from Plaud before using it with patients. Contact them directly. If they will not sign one, do not use it with PHI.
-
Obtain documented patient consent. Use standardized consent forms that specifically mention AI-powered transcription. Verbal consent should be documented in the medical record.
-
Offer clear opt-out options. Patients must be able to decline recording without it affecting their care.
-
Conduct a security risk assessment specific to your use of ambient recording technology, as required by HIPAA.
-
Follow the most protective standard. Comply with both HIPAA and your state's recording and medical privacy laws.
-
Do not rely on Plaud's transcriptions as clinical documentation without review. The Sharp HealthCare lawsuit shows the risk of auto-generated clinical notes without verification.
For Business Users
-
Include recording notices in meeting invitations so participants are informed in advance.
-
Use active consent prompts in virtual meetings. Do not rely on passive platform notifications alone.
-
Update your company's recording policy to specifically address AI transcription tools. Many businesses adopted these tools without updating their policies.
-
Be especially careful in hybrid meetings. Remote attendees may be in different states with different consent requirements.
-
Establish a data retention policy. Keeping recordings indefinitely creates ongoing legal exposure.
Our Assessment
Plaud's security infrastructure is genuinely strong for a consumer-grade AI recording device. The SOC 2 Type II certification, AES-256 encryption, and zero-training data guarantee put it ahead of many competitors on the technical security front.
But their "just ask first" consent guidance is inadequate, and the absence of a publicly available BAA is a significant gap given how aggressively they market to healthcare professionals. A SOAP note template is not a compliance program.
If you are in healthcare: get the BAA in writing before touching patient audio. If Plaud will not provide one, use a competitor that will. The convenience of the hardware is not worth the compliance risk.
If you are using Plaud for business: assume the strictest state law in the room applies and ask consent upfront. It protects you legally and it is simply the right thing to do.
For personal note-taking and voice memos where you are the only party: you are fine. That is where the Plaud NotePin works without legal complications.
Frequently Asked Questions
Is Plaud HIPAA compliant?
Plaud has obtained HIPAA certification verified through Drata, alongside SOC 2 Type II, GDPR, and ISO 27001/27701 certifications. However, HIPAA certification alone does not make healthcare use automatically compliant. Healthcare providers need a signed Business Associate Agreement (BAA) before using Plaud with patient data, and there is no public evidence that Plaud currently offers one.
Does Plaud offer a Business Associate Agreement (BAA)?
As of August 2026, there is no publicly available evidence that Plaud offers a BAA. Their healthcare solution page, enterprise FAQ, trust page, and support documentation do not mention BAAs. Healthcare providers should contact Plaud directly to request one before using the device with any patient information.
Can I use Plaud to record patient sessions?
Technically you can, but without a signed BAA from Plaud, doing so with identifiable patient information constitutes a HIPAA violation. You also need explicit patient consent for the recording, and must comply with your state's recording consent laws. Some states require all-party consent, meaning the patient must affirmatively agree before recording begins.
What states require all-party consent to record?
As of 2026, the all-party consent states are California, Connecticut (civil liability), Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington. Oregon's all-party rule applies to in-person conversations under ORS 165.540(1)(c), while telecommunications there follow a one-party standard. Nevada runs the opposite way, requiring all-party consent for phone calls but only one-party for in-person conversations. Michigan's status remains legally unsettled.
Does Oregon require consent to record an in-person conversation?
Yes. ORS 165.540(1)(c) makes it unlawful to obtain any part of a conversation using a recording device unless all participants are specifically informed that their conversation is being obtained. A violation is a Class A misdemeanor. This matters for wearable recorders like the Plaud NotePin, because the stricter Oregon rule applies to exactly the in-person encounters those devices are designed to capture.
What are the penalties for recording without consent?
Penalties vary by state but can be severe. In Pennsylvania, illegal recording is a third-degree felony carrying up to 7 years in prison and a $15,000 fine. In Massachusetts, it can mean up to 5 years and $10,000. In Florida, it is a third-degree felony with up to 5 years. Federal violations under 18 U.S.C. 2511 carry up to 5 years imprisonment and $250,000 in fines.
What HIPAA-compliant alternatives to Plaud offer BAAs?
DeepScribe, Freed, and Supanote publicly document BAAs in their own materials, and Fireflies.ai offers a BAA on its Enterprise plan. Nabla does not publicly state that it offers a BAA, and Otter.ai lists HIPAA compliance only as an Enterprise add-on without naming a BAA, so confirm with those vendors in writing before any patient use. Vendor terms change, so always confirm which contracting tier includes the BAA and keep the executed copy. None of these replicate Plaud's wearable hardware form factor for in-person recording.
Does Plaud's speaker identification feature create BIPA risks in Illinois?
Potentially, yes. Illinois's Biometric Information Privacy Act defines a biometric identifier to include a voiceprint under 740 ILCS 14/10. Plaud's speaker identification feature, which distinguishes between speakers in a conversation, could qualify as voiceprint collection under BIPA, requiring written notice and signed authorization from each individual. BIPA provides liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorneys' fees.
Updates
Governing law re-checked for recent changes
Corrected the all-party consent table to include Oregon, whose ORS 165.540 in-person recording rule is the one most likely to apply to a wearable recorder, and corrected Delaware's penalty from felony to class A misdemeanor under 11 Del. C. 1335(c), citing the Delaware Code directly. Re-verified every vendor in the HIPAA alternatives table against the vendor's own current materials: DeepScribe, Freed, Supanote, and Fireflies.ai (Enterprise) publicly document BAAs, while Nabla and Otter.ai do not publicly state one, and an unverifiable vendor was removed. Also corrected the court for Cruz v. Fireflies.AI Corp. to the Central District of Illinois, restated Ambriz v. Google as a motion-to-dismiss ruling rather than a merits holding, tied the Sharp HealthCare lawsuit description to its December 2025 reporting and named the Abridge tool, widened California AB 3030's covered entities to match the statute, and removed an unsourced $500 penalty figure attached to California AB 2905.
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Penal Code
§ 632In forcecited in 39 of our articles
(a) A person who, intentionally and without the consent of all parties to a confidential communication, uses an electronic amplifying or recording device to eavesdrop upon or record the confidential communication, whether the communication is carried on among the parties in the presence of one another or by means of a telegraph, telephone, or other device, except a radio, shall be punished by a fine not exceeding two thousand five hundred dollars ($2,500) per violation, or imprisonment in a county jail not exceeding one year, or in the state prison, or by both that fine and imprisonment. If the person has previously been convicted of a violation of this section or Section 631, 632.5, 632.6, 632.7, or 636, the person shall be punished by a fine not exceeding ten thousand dollars ($10,000) per violation, by imprisonment in a county jail not exceeding one year, or in the state prison, or by both that fine and imprisonment.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 267 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Kimmel v. Goland (1990) held the section 47(2) litigation privilege does not bar a damages claim under Section 632 for recording confidential conversations without consent. Lieberman v. KCOP Television, Inc. (2003) held a Section 632 violation is complete the moment the recording is made, whether or not it is disclosed.
Opinions citing this section in our collection:
- Rubin v. Green (California Supreme Court 1993, 4 Cal. 4th 1187)“…f telephone conversations with defendants, an offense under Penal Code section 632. We noted that defendants alleged that…”
- Kimmel v. Goland (California Supreme Court 1990, 51 Cal. 3d 202)✓Mobilehome owners secretly taped phone calls with park management in anticipation of suing; the court held the section 47(2) litigation privilege did not bar the cross-complaint for damages under Penal Code section 632, since the injury came from recording, not publication.
- Shulman v. Group W Productions, Inc. (California Supreme Court 1998, 74 Cal. Rptr. 2d 843)✓A TV producer put a wireless microphone on the flight nurse treating a crash victim. No section 632 claim was before the court, but it called section 632 and the intrusion tort laws of general applicability and said the press may not eavesdrop in violation of section 632.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Florida Statutes
§ 934.03Interception and disclosure of wire, oral, or electronic communications prohibited.In forcecited in 51 of our articles
(1) Except as otherwise specifically provided in this chapter, any person who:(a) Intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept any wire, oral, or electronic communication; (b) Intentionally uses, endeavors to use, or procures any other person to use or endeavor to use any electronic, mechanical, or other device to intercept any oral communication when:1. Such device is affixed to, or otherwise transmits a signal through, a wire, cable, or other like connection used in wire communication; or 2.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leg.state.fl.us
Cited in 74 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):State v. Walls (1978) held that recording an in-home oral communication without the consent of all parties violated section 934.03 and required suppression, and State v. Inciarrano (1985) held the statute protects only communications uttered with a reasonable expectation of privacy.
Opinions citing this section in our collection:
- State v. Walls (Supreme Court of Florida 1978, 356 So. 2d 294)✓An extortion victim secretly recorded threats made to him in his own home; the court held that was a protected oral communication, that recording it without every party's consent violated Section 934.03, and that Section 934.06 barred using the tape as evidence.
- SHARRON TASHA FORD v. CITY OF BOYNTON BEACH (District Court of Appeal of Florida 2021)“…ng oral communications in violation of the wiretap statute, section 934.03, Florida Statutes (2009), and for obstructing without vio…”
- State v. Calhoun (Circuit Court for the Judicial Circuits of Florida 1984, 7 Fla. Supp. 2d 3)“…hall not be violated” . . . (emphasis mine) Furthermore, section 934.03, Florida Statutes, makes it unlawful for *6 any person (…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Maryland Code, Courts and Judicial Proceedings Article
§ 10-402In forcecited in 26 of our articles
§10–402. (a) Except as otherwise specifically provided in this subtitle it is unlawful for any person to: (1) Willfully intercept, endeavor to intercept, or procure any other person to intercept or endeavor to intercept, any wire, oral, or electronic communication; (2) Willfully disclose, or endeavor to disclose, to any other person the contents of any wire, oral, or electronic communication, knowing or having reason to know that the information was obtained through the interception of a wire, oral, or electronic communication in violation of this subtitle; or (3) Willfully use, or endeavor to use, the contents of any wire, oral, or electronic communication, knowing or having reason to know that the information was obtained through the interception of a wire, oral, or electronic communication in violation of this subtitle. (b) Any person who violates subsection (a) of this section is guilty of a felony and is subject to imprisonment for not more than 5 years or a fine of not more than $10,000, or both.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Cited in 12 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Applying section 10-402, Fearnow v. Chesapeake & Potomac Telephone Co. (1995) held that liability under the Maryland Wiretap Act requires proof the defendant acted willfully, an intentional violation or reckless disregard of a known legal duty; an employee's failure to check for a court order was only a jury factor on willfulness.
Opinions citing this section in our collection:
- Fearnow v. Chesapeake & Potomac Telephone Co. (Court of Special Appeals of Maryland 1995, 104 Md. App. 1)✓Police hid a tape recorder on an officer's headquarters phone line with a phone company employee's help and no court order; the court held a section 10-402(a) claim requires proof of willful interception, and failing to ask about a court order went only to willfulness.
- Maryland Attorney General Opinion 110OAG60 (Maryland Attorney General Reports 2025)“…or wire communications without the consent of all parties. Md. Code Ann., Cts. & Jud. Proc. § 10-402(a). However, the Wiretap Act contains e…”
- Boehner, John A. v. McDermott, James A. (Court of Appeals for the D.C. Circuit 1999, 191 F.3d 463)“…1992); Me.Rev.Stat. Ann. tit. 15, §§ 710, 711 (West 1998); Md.Code Ann., Cts & Jud. Proc. § 10-402 (1998); Mass. Gen. Laws Ann. ch. 272,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Michigan Compiled Laws
§ 750.539cEavesdropping upon private conversationIn forcecited in 42 of our articles
Any person who is present or who is not present during a private conversation and who wilfully uses any device to eavesdrop upon the conversation without the consent of all parties thereto, or who knowingly aids, employs or procures another person to do the same in violation of this section, is guilty of a felony punishable by imprisonment in a state prison for not more than 2 years or by a fine of not more than $2,000.00, or both.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 32 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Michigan courts read MCL 750.539c to reach third-party eavesdropping only. Sullivan v. Gray (1982) held the statutory phrase "private discourse of others" excludes recording by a participant in the conversation; People v. Lucas (1991) held an officer who answered an arrestee's ringing car phone did not violate the section.
Opinions citing this section in our collection:
- People v. Lucas (Michigan Court of Appeals 1991, 188 Mich. App. 554)✓Police answering the arrested defendant's ringing car phone took drug-purchase calls and testified to them; the court held the officer was not an eavesdropper because there was no private discourse between the sender and some other receiver, so MCL 750.539c was not violated.
- Sullivan v. Gray (Michigan Court of Appeals 1982, 117 Mich. App. 476)✓A party to a phone call about a failed car dealership sale secretly taped it and the transcript was used in later litigation; reading the statute to reach only the private discourse of others, the court held participant recording is not eavesdropping under MCL 750.539c.
- People v. Warner (Michigan Supreme Court 1977, 401 Mich. 186)✓A motel switchboard operator deliberately listened in on a guest's call and reported it to police; the court held her willful eavesdropping violated MCL 750.539c, but the defendant, not shown to be a party to the call, had no standing to suppress the resulting evidence.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Revised Code of Washington
§ 9.73.030Intercepting, recording, or divulging private communication—Consent required—Exceptions.In forcecited in 41 of our articles
(1) Except as otherwise provided in this chapter, it shall be unlawful for any individual, partnership, corporation, association, or the state of Washington, its agencies, and political subdivisions to intercept, or record any: (a) Private communication transmitted by telephone, telegraph, radio, or other device between two or more individuals between points within or without the state by any device electronic or otherwise designed to record and/or transmit said communication regardless how such device is powered or actuated, without first obtaining the consent of all the participants in the communication; (b) Private conversation, by any device electronic or otherwise designed to record or transmit such conversation regardless how the device is powered or actuated without first obtaining the consent of all the persons engaged in the conversation.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at app.leg.wa.gov
Cited in 221 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Washington courts have policed what counts as a private communication under Sec. 9.73.030: State v. Gunwall (1986) concluded a pen register intercept comes within a private communication transmitted by telephone, while State v. Riley (1993) held a line trap that reveals only the calling number does not record one.
Opinions citing this section in our collection:
- State v. Salinas (Washington Supreme Court 1992, 119 Wash. 2d 192)“…alties for divulging a telegram or opening a sealed letter. RCW 9.73.030-.070, making it unlawful to intercept,…”
- State v. Gunwall (Washington Supreme Court 1986, 106 Wash. 2d 54)✓Everett police pulled a suspected cocaine dealer's toll records and put a pen register on her line without valid legal process; the court held a pen register intercept is a private communication transmitted by telephone, installable only under the eavesdropping statutes.
- State v. Brown (Washington Supreme Court 1997, 132 Wash. 2d 529)✓Palm Springs officers secretly recorded a Washington murder suspect's statements after his arrest; the court treated RCW 9.73.090, not 9.73.030, as the provision reaching recordings of arrested persons, and held the Privacy Act did not require suppressing that recording.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 18
§ 2511Interception and disclosure of wire, oral, or electronic communications prohibitedIn forcecited in 418 of our articles
Except as otherwise specifically provided in this chapter any person who— intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept, any wire, oral, or electronic communication; intentionally uses, endeavors to use, or procures any other person to use or endeavor to use any electronic, mechanical, or other device to intercept any oral communication when— such device is affixed to, or otherwise transmits a signal through, a wire, cable, or other like connection used in wire communication; or such device transmits communications by radio, or interferes with the transmission of such communication; or such person knows, or has reason to know, that such device or any component thereof has been sent through the mail or transported in interstate or foreign commerce; or such use or endeavor to use (A) takes place on the premises of any business or other commercial establishment the operations of which affect interstate or foreign commerce; or (B) obtains or is for the purpose of obtaining information relating to the operations of any business or other commercial establishment the operations of which affect interstate or foreign…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 2,045 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Griggs-Ryan v. Smith (1990) applied the Section 2511(2)(d) prior-consent exception, treating a tenant repeatedly told that all incoming calls were taped as having impliedly consented. United States v. United States District Court (1972) read the then-current Section 2511(3) as conferring no presidential surveillance power.
Opinions citing this section in our collection:
- Mitchell v. Forsyth (Supreme Court of the United States 1985, 472 U.S. 511)✓The Attorney General authorized a warrantless 1970 national security wiretap that caught the plaintiff's calls; the Court held the since-repealed Section 2511(3) disclaimer left the tap lawful under Title III, and that Mitchell had qualified immunity.
- United States v. United States District Court for the Eastern District of Michigan (Supreme Court of the United States 1972, 407 U.S. 297)✓The Attorney General approved warrantless wiretaps on members of a domestic group accused of bombing a CIA office; the Court read Section 2511(3) as a congressional disclaimer conferring no surveillance power, then held the Fourth Amendment required prior judicial approval.
- Forsyth v. Barr (Court of Appeals for the Fifth Circuit 1994, 19 F.3d 1527)✓Dallas police used, in an internal affairs probe of an officer, calls private parties allegedly intercepted illegally; assuming that was unlawful, the Fifth Circuit held Section 2517(1) and (2) allowed the disclosure and use, defeating the Section 2511(1)(c) and (d) claims.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 2520Recovery of civil damages authorizedIn forcecited in 115 of our articles
Except as provided in section 2511(2)(a)(ii), any person whose wire, oral, or electronic communication is intercepted, disclosed, or intentionally used in violation of this chapter may in a civil action recover from the person or entity, other than the United States, which engaged in that violation such relief as may be appropriate. In an action under this section, appropriate relief includes— such preliminary and other equitable or declaratory relief as may be appropriate; damages under subsection (c) and punitive damages in appropriate cases; and a reasonable attorney’s fee and other litigation costs reasonably incurred.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 860 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Walker v. Darby (1990) held a 2520 plaintiff need not prove the contents of intercepted conversations, only interception and a justified expectation against it. Bartnicki v. Vopper (2001) barred 2520 damages against defendants who took no part in the interception, obtained the tape lawfully, and disclosed a matter of public concern.
Opinions citing this section in our collection:
- Jessie Walker v. Thomas E. Darby, Hugh L. Robinson, Jr., and Kenneth Day (Court of Appeals for the Eleventh Circuit 1990, 911 F.2d 1573)✓A postal letter carrier said three supervisors wired an intercom near his workstation to listen in. Reversing summary judgment, the Eleventh Circuit held a section 2520 plaintiff can show interception without proving the contents of specific conversations.
- Gelbard v. United States (Supreme Court of the United States 1972, 408 U.S. 41)“…disclosure, or use is entitled to recover civil damages, 18 U. S. C. § 2520 . Title III also bars the use as eviden…”
- DirecTV, Inc. v. Hoa Huynh (Court of Appeals for the Ninth Circuit 2007, 503 F.3d 847)“…7 U.S.C. § 605 (e)(4), or alternatively, for violations of 18 U.S.C. § 2520 (a), or alternatively, for violations o…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Is Plaud HIPAA Compliant? Plaud Support(support.plaud.ai)
- Plaud Trust Center(plaud.ai)
- Plaud Data Security & Privacy(plaud.ai)
- Plaud: What Certifications Has Plaud Achieved?(support.plaud.ai)
- Plaud Healthcare Solution(plaud.ai)
- Plaud GDPR Compliance Announcement(plaud.ai)
- Business Associate Contract Provisions, HHS(hhs.gov).gov
- Business Associates Guidance, HHS(hhs.gov).gov
- HIPAA Audio Telehealth Guidance, HHS(hhs.gov).gov
- HHS Adjusts 2026 HIPAA Penalties(mercer.com)
- 18 U.S.C. § 2511, Interception of Communications(law.cornell.edu)
- 18 U.S.C. § 2520, Civil Damages for Wiretap Violations(law.cornell.edu)
- California Penal Code § 632(leginfo.legislature.ca.gov).gov
- Florida Statute § 934.03(leg.state.fl.us).gov
- Illinois 720 ILCS 5/14-2(ilga.gov).gov
- Delaware Code Title 11 § 1335, Violation of Privacy(delcode.delaware.gov).gov
- Delaware Code Title 11 § 2402, Interception of Communications(delcode.delaware.gov).gov
- Illinois BIPA, 740 ILCS 14/10 (Definitions, including voiceprint)(ilga.gov).gov
- Illinois BIPA, 740 ILCS 14/20 (Right of Action and Damages)(ilga.gov).gov
- Maryland Courts & Judicial Proceedings § 10-402(mgaleg.maryland.gov).gov
- Massachusetts General Laws Ch. 272, § 99(malegislature.gov).gov
- Oregon ORS 165.540, Obtaining Contents of Communications(oregonlegislature.gov).gov
- Nevada NRS 200.620, Interception of Wire Communication(leg.state.nv.us).gov
- Washington RCW 9.73.030(app.leg.wa.gov).gov
- California AB 2905, Artificial Voice Disclosure in Prerecorded Calls(leginfo.legislature.ca.gov).gov
- California AB 3030, Generative AI Disclaimers in Patient Communications(leginfo.legislature.ca.gov).gov
- FCC: TCPA Applies to AI Voices(fcc.gov).gov
- Ambriz v. Google and the CIPA Capability Test(natlawreview.com)
- Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 (C.D. Ill.), Docket via CourtListener(courtlistener.com)
- Lawsuit Claims Sharp HealthCare Secretly Recorded Exam Room Conversations, KPBS(kpbs.org)
- Health System Sued Over AI Scribe Technology and Patient Consent(medscape.com)
- The Legality of AI-Powered Recording and Transcription, Reed Smith(reedsmith.com)